Repository navigation
62 lines (53 loc) · 2.28 KB
/
Copy pathrelease.yml
File metadata and controls
62 lines (53 loc) · 2.28 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
# SPDX-License-Identifier: MPL-2.0
name: release
# Build the Windows binary (only possible on a Windows runner) and publish it
# with the installer scripts on a tagged release.
on:
push:
tags: ["v*"]
workflow_dispatch:
permissions:
actions: read
contents: write
jobs:
windows-release:
runs-on: windows-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Rust
run: rustup toolchain install stable --profile minimal
- name: Build release binary
working-directory: host-rust
run: cargo build --release
- name: Run tests
working-directory: host-rust
run: cargo test --release
- name: Optional code signing
if: ${{ env.WINDOWS_PFX_BASE64 != '' }}
env:
WINDOWS_PFX_BASE64: ${{ secrets.WINDOWS_PFX_BASE64 }}
WINDOWS_PFX_PASSWORD: ${{ secrets.WINDOWS_PFX_PASSWORD }}
shell: pwsh
run: |
[IO.File]::WriteAllBytes("cert.pfx", [Convert]::FromBase64String($env:WINDOWS_PFX_BASE64))
& "${env:ProgramFiles(x86)}\Windows Kits\10\bin\x64\signtool.exe" sign `
/f cert.pfx /p $env:WINDOWS_PFX_PASSWORD /fd SHA256 /tr http://timestamp.digicert.com /td SHA256 `
host-rust\target\release\lsa-sentinel.exe
Remove-Item cert.pfx
- name: Stage package
shell: pwsh
run: |
New-Item -ItemType Directory -Force dist | Out-Null
Copy-Item host-rust\target\release\lsa-sentinel.exe dist\
Copy-Item installer\*.ps1 dist\
Copy-Item installer\README.md dist\INSTALL.md
Compress-Archive -Path dist\* -DestinationPath "lsa-sentinel-${{ github.ref_name }}-x86_64-windows.zip" -Force
- name: Publish release
shell: pwsh
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release create "${{ github.ref_name }}" `
"lsa-sentinel-${{ github.ref_name }}-x86_64-windows.zip" `
--title "lsa-sentinel ${{ github.ref_name }}" `
--notes "Windows build + installer. Verdicts route to the Application event log (source 'lsa-sentinel'; Error 1001 = BLOCKED-INERT). See INSTALL.md. NOTE: collectors not yet field-validated; 0patch collector is a placeholder (fails safe)."